Live data from Hacker News

Heroku Invoice Security Issue - You can see anyone's invoice

news.ycombinator.com

21–27 of 27 posts

Re: Heroku Invoice Security Issue - You can see anyone's invoice

#21
post #15

Earlier quoted context omitted.

Click on 'current usage' in your account and it takes you to your current invoice, which is accessible via the URL that he mentions. It appears to be only the current months usage / invoice that is vulnerable.

EDIT: removing URLs because it's the right thing to do.

Yikes - so are past invoices available as well then via the show/:id url?

Re: Heroku Invoice Security Issue - You can see anyone's invoice

#23
post #18

Why do people use Heroku? I never understood the appeal. Oh.. because they have a good graphic designer. Lol. "Forget servers, instances, and VMs. Focus on processes." If that doesn't raise some red flags for you then you get what you deserve.

Yep, $212 million in value built in an extremely short time. Because of a good graphic designer, sure.

More likely by charging $6400/month for 68GB of RAM.

That's less then $100/GB/Month.

With low prices like that it must be hard for people to resist.

Re: Heroku Invoice Security Issue - You can see anyone's invoice

#26
This is REALLY bad. You should have given them at least a day to fix it before posting it here though, this is pretty bad etiquette. I understand you're excited you discovered such a stupid mistake but everyone can just pull up my payment details by entering the correct URL now.

Re: Heroku Invoice Security Issue - You can see anyone's invoice

#27

I'm pretty appalled that you submitted this to, arguably, one of the most-visited sites for tech news, without at least giving them time to address the problem. This isn't a case of something small going unnoticed, resulting in a bit of a laugh and giggle. This is people's billing details, and you've just explained how to exploit the bug in complete detail. I'm really unhappy that this sort of thing even crossed your…

On one hand, I do see your point - at first glance it seems a bit unfair to ambush them like this. On the other hand, if the OP quietly submits it to Heroku and they fix it, then none of us find out. Posting about a vulnerability that has recently been fixed would not be likely to garner nearly as much attention as one that is an open issue.

This is the sort of thing that I, as a Heroku customer, really want to no about. Not because my personal information is at risk - no credit card #'s or anything are accessible - but because it changes my perspective on Heroku. This vulnerability is just plain sloppy on their part - I really though that the folks at Heroku were smarter than this.

If this leak provided access to any more sensitive data, like credit card #'s or SSN's I would 100% agree with you - notify Heroku and let them fix it first. But the only real harm I see coming from this being posted pre-fix is embarrassment for Heroku.

Post reply on HN